The Vvveb software by givanz has known security vulnerabilities that could allow unauthorized access or execution of arbitrary code.
Claims
The Vvveb software by givanz has known security vulnerabilities that could allow unauthorized access or execution of arbitrary code.
Parent: CybersecurityEntity: Vvveb software by givanzImpact: negativeDate: Apr 20, 2026Target: The security of the Vvveb software by givanz
Source posts
๐จ EUVD-2026-23854
๐ Score: 5.1/10 (CVSS v3.1)
๐ฆ Product: Vvveb, Vvveb
๐ข Vendor: givanz
๐
Updated: 2026-04-20
๐ Vvveb prior to 1.0.8.1 contains a stored cross-site scripting vulnerability that allows authenticated users with media upload and rename permissions to execute arbitrary JavaScript by bypassing MIME type validation and renaming uploaded files to executab...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-23854
#cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 20, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
๐จ EUVD-2026-23852
๐ Score: 8.3/10 (CVSS v3.1)
๐ฆ Product: Vvveb, Vvveb
๐ข Vendor: givanz
๐
Updated: 2026-04-20
๐ Vvveb prior to 1.0.8.1 contains a server-side request forgery vulnerability in the oEmbedProxy action of the editor/editor module where the url parameter is passed directly to getUrl() via curl without scheme or destination validation. Authenticated back...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-23852
#cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 20, 2026
#cybersecurity#infosec#euvd#cve#vulnerability